Splunk Enterprise

Discrepancy with License Usage

sivakrishna
Path Finder

 

Hi Team,

We are facing discrepancy with Splunk License total usage vs Index wise usage.

Could you please help us on this? 

Our Actual Splunk Stack is 50GB.

1. Index wise License Usage:

MicrosoftTeams-image (4).png

 

for individual index for 1 index showing 65.46GB for the same day Total usage we are getting 55.42GB as shown in below screen shots.

2. Total License Usage:

This is the Overall License usage for Feb 15.

MicrosoftTeams-image (5).png

 

Kindly assist us with License Usage query based on index wise and it should match with the total License Usage and indicate any changes that need to be made at the server or configuration level.

@gcusello @isoutamo @PickleRick

Regards,

Siva.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. You posted the same question twice already.

2. Calling out specific people to help you is simply rude.

3. It's a case for support.

0 Karma

sivakrishna
Path Finder

Hi Rick,

My apologize for that. I am not aware of this.

We are actually rushing on this issue bcz its on priority in our PROD environment.

I dnt know how to tag people earlier i have posted without tagging.

I won't repeat this again.

Regards,

Siva

0 Karma

PickleRick
SplunkTrust
SplunkTrust

No. You should _not_ tag people when asking questions.

This is a community-driven forum when people voluntarily help others in their own time. Tagging people when asking question can be perceived as demanding answer from such person. You can demand... well, if you buy a paid consultancy service, quite frankly.

This is a place for sharing ideas and experiences, it's not meant as a replacement for support or as a free labor.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...